The NIS2 Challenge in Hospitals
NIS2 compliance:
a migration guide for hospital access.
The European NIS2 directive imposes strengthened cybersecurity requirements for healthcare institutions. This guide proposes a compliant migration path, prioritizing interoperability and intelligent asset reuse to control budgetary impact.

Healthcare facilities — zoned access
01
Existing System Audit: Identifying Compromise Vectors
The first step is to assess the vulnerability of communication protocols. Many hospitals still use obsolete protocols that pose a major risk to data and access security.
The Wiegand vs. OSDP Risk
The Wiegand protocol transmits badge data in plain text. A simple cable tap allows a badge to be cloned. NIS2 requires data flow protection. Transitioning to OSDP (Open Supervised Device Protocol) v2.2, which uses AES-128 encryption, is imperative.
Engineer's Tip
Don't replace everything immediately. Identify 'sensitive' areas (Pharmacy, Operating Theaters, Data Center) for priority OSDP migration, while initially retaining Wiegand in low-risk administrative areas.
02
Modernizing Credentials
Security relies on the ISO/IEC 14443 standard (contactless proximity objects). Widely used 125kHz badges are easily clonable and must be replaced to achieve the required security level.
Cost-controlled approach: Adopt multi-technology readers (e.g., HID OMNIKEY 5422) capable of reading both old badges and new, secure credentials. This allows for a smooth, multi-year badge migration without service interruption.
Standard
Recommended standard: MIFARE DESFire EV2/EV3.
Sécurité
Security: Mutual encryption and digital data signing.
03
Physical and Logical Convergence: The FIDO2 Lever
NIS2 emphasizes strong authentication (MFA). For healthcare staff, the proliferation of passwords is an operational hindrance. The solution is convergence. Using protocols like FIDO2 (WebAuthn / CTAP) allows the hospital badge to be used as an authentication factor on workstations (Single Sign-On). By relying on FIDO Alliance specifications, the institution reduces phishing risks while improving user experience.

Physical + logical convergence
04
Architecture and Governance: Applying PoLP
The Principle of Least Privilege (PoLP) must govern system logic. In a healthcare environment, access should be dynamic (ABAC - Attribute-Based Access Control) rather than static for granular security.
MODEL
NIS2 APPLICATION
COST BENEFIT
RBAC (Role-Based)
Groups by profession (Nurses, Doctors)
Simplicity of initial setup
ABAC (Attribute-Based)
Access conditioned by schedule and on-call service
Surgical precision of security
05
PKI Infrastructure and Certificate Lifecycle
According to ANSSI (Guide 'Back to Basics PKI'), a robust key management infrastructure is the foundation of trust. For healthcare institutions, this translates into clear requirements.
Automation: Use protocols like ACME for renewing certificates on your access control servers.
Automation: Use protocols like ACME for renewing certificates on your access control servers.
Independence: Separate roles (Administrator vs. Operator) to prevent a single compromise from paralyzing the entire system.
Independence: Separate roles (Administrator vs. Operator) to prevent a single compromise from paralyzing the entire system.
06
NIS2 Migration Checklist (Technical Summary)
Migration of critical readers to OSDP protocol (encrypted RS-485).
Deployment of ISO/IEC 14443 compliant badges (MIFARE DESFire).
Implementation of MFA via FIDO2/WebAuthn for sensitive logical accesses.
Quarterly audit of access control logs and rights (RBAC/ABAC).
Securing integration APIs between security software and HR (NIST 800-63B Standard).
Ready to secure your institution?
Contact our experts for a NIS2 compliance audit and a tailored migration plan.